PCI DSS 4.0, requirement by requirement.
All 12 requirements and 351 controls of version 4.0.1, with evidence attached where the assessor will look for it.
4.0 raised the bar
PCI DSS 4.0 is not a refresh. It added customised implementation, tightened authentication, expanded logging and scripting requirements, and pushed a set of previously best-practice items into mandatory status.
If you handle cardholder data, the requirement applies whether you are filling in a self-assessment questionnaire or engaging a QSA for a Report on Compliance. Either way you are evidencing 12 requirements across hundreds of sub-requirements, annually.
OpenGRC includes the full PCI DSS 4.0.1 bundle — 351 controls including the Appendix A requirements for shared hosting and service providers — on every plan.
Evidence where the assessor looks.
Scoped to your environment
Applicability is set per control, so the requirements that do not apply to your cardholder data environment are recorded as such with a reason, rather than quietly ignored.
Evidence attached to sub-requirements
PCI assessment is granular. Each control carries its implementation, test procedure and evidence, so when an assessor asks about 8.3.6 the answer and its proof are in the same place.
A portal for your QSA
Your assessor gets an MFA-protected panel with time-bounded, revocable access, IP allow-listing and immutable versioned submissions — and you get a record of everything they opened.
The 12 requirements
| Requirement | Controls |
|---|---|
| 1 Network security controls | 24 |
| 2 Secure configurations | 14 |
| 3 Protect stored account data | 36 |
| 4 Protect data in transit | 8 |
| 5 Anti-malware | 17 |
| 6 Secure systems and software | 24 |
| 7 Restrict access by business need | 15 |
| 8 Identify users and authenticate | 35 |
| 9 Restrict physical access | 32 |
| 10 Log and monitor | 34 |
| 11 Test security regularly | 27 |
| 12 Policies and programmes | 47 |
| A1 / A3 Multi-tenant and designated entities | 34 |
PCI DSS questions
Which version is included?
PCI DSS 4.0.1, the current revision, with 351 controls covering all 12 requirements plus the Appendix A requirements for multi-tenant service providers and designated entities.
™